First published: Wed Jan 12 2011(Updated: )
Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Server | =5.0.2 | |
BlackBerry Enterprise Server | =4.1.7 | |
BlackBerry Enterprise Server | =4.1.6-mr4 | |
BlackBerry Enterprise Server | =4.1.5 | |
BlackBerry Enterprise Server | =4.1.4 | |
BlackBerry Enterprise Server | =5.0.0 | |
BlackBerry Enterprise Server | =4.1.6 | |
BlackBerry Enterprise Server | =4.1.3 | |
BlackBerry Enterprise Server | =5.0.1 | |
BlackBerry Enterprise Server Express | =5.0.1 | |
BlackBerry Enterprise Server Express | =5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2604 has a high severity rating due to the potential for remote code execution.
To mitigate CVE-2010-2604, upgrade your BlackBerry Enterprise Server to the latest version provided by RIM.
CVE-2010-2604 affects BlackBerry Enterprise Server versions from 4.1.3 to 5.0.2 and BlackBerry Enterprise Server Express versions 5.0.1 and 5.0.2.
Yes, CVE-2010-2604 can be exploited remotely through a specially crafted PDF file.
The exploitation of CVE-2010-2604 could allow attackers to execute arbitrary code on the affected BlackBerry servers.